documentation-lookup
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves documentation from an external service and incorporates it into the agent's context, creating a surface where malicious or manipulated documentation could attempt to influence the agent's behavior.
- Ingestion points: User queries and documentation snippets fetched via the resolve-library-id and query-docs MCP tools (SKILL.md).
- Boundary markers: None explicitly defined to isolate or neutralize the external documentation snippets.
- Capability inventory: Network access through platform-configured MCP tools (SKILL.md).
- Sanitization: The skill mandates redacting secrets from queries, but does not provide instructions for sanitizing the documentation returned from the external service.
- [DATA_EXFILTRATION]: The skill transmits user-provided questions to the external Context7 documentation service, which constitutes a network operation to a non-whitelisted domain.
- Evidence: User questions are used as the 'query' parameter for external tool calls to improve document relevance (SKILL.md).
- Mitigation: The skill includes a clear 'No sensitive data' directive, instructing the agent to redact API keys, passwords, and tokens before they are sent to the external service.
Audit Metadata